Security News

Cybersecurity news aggregator

🔄
INFO Updates Debian Security

DSA-6329-1 tomcat11 - security update

  • What: Tomcat11 receives multiple security updates
  • Impact: Fixes vulnerabilities in the web server
Read Full Article →

[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6329-1] tomcat11 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6329-1] tomcat11 security update From: Markus Koschany <apo@debian.org> Date: Mon, 8 Jun 2026 13:00:58 +0000 Message-id: <[🔎] aia9Cox8uTXqeFJ6@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6329-1 security@debian.org https://www.debian.org/security/ Markus Koschany June 08, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tomcat11 CVE ID : CVE-2026-24734 CVE-2026-24880 CVE-2026-25854 CVE-2026-29129 CVE-2026-29145 CVE-2026-29146 CVE-2026-32990 CVE-2026-34483 CVE-2026-34487 CVE-2026-34500 CVE-2026-41284 CVE-2026-41293 CVE-2026-42498 CVE-2026-43512 CVE-2026-43513 CVE-2026-43514 CVE-2026-43515 Multiple security vulnerabilities have been discovered in Tomcat 11, a Java based web server, servlet and JSP engine which may result in a denial of service, authentication bypass or the disclosure of sensitive information. Although we are not aware of any problems, new upstream versions may introduce new options, limits or code changes which may or may not affect your existing web applications. We recommend to consult the Tomcat 11 documentation for further information. For the stable distribution (trixie), these problems have been fixed in version 11.0.22-1~deb13u1. We recommend that you upgrade your tomcat11 packages. For the detailed security status of tomcat11 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tomcat11 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmomtKVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeS8aBAAkRHBQSksEUcj+4/sCyMsFbX2EbjGu6m36o213mp/fVRgyYk7VvNH0PBG y/7/FRILF/0LiFlOXo/7jsOZm5VeQukCdTB8CCVaFi//kerjii+aBxZUCHWpe8Np F4BYRjYVp6J7/WRAoDPcZjNT1eDcOlmrbydCigm0JYfvqSycYHBdTaMwHQHCwM16 InL3ZB7EU3rcwxKwrY4SMHYrv1IE/1ZIX0QezCi/2RmD+X1aov4w4Uvmy+k/oocF mHPzDOkv2oyDJ3X6VnnJuTo7rJ7BBcyLF1SaXSk2D8YPAfjNNOrwjSUp4JA6TjKI ugLVHTTQtx9Le1f0nPHuyRXi7P11itD9gWOnLVso99ogPnp/oY9LRjnfCtw1LVyB 26ANPTLWPI40fvdGsPckKmA6j1ap3sCqvLsgOWAMVHpoI2BrGe8UzGRdjqIr9MHV F9twx9PT5hpqHptGbc60iWR7av/A4Rk8WVdZi/Nor64F+oiR2TALs/JZr6QUjvkm eTOuvpjmVGmqOjvpi9p43LRFSBSbjs3OsUtHX2655uYLUgcsFqn/NZMeuikjgUYk zlNvfCfzL6SFU0mziTK2JcOTn3t/wh1EzgAfdgxiBJ5F2z0jfIfGt5mKEP4GcswL kXNtiJVJ1kRucreUKSv9mp5s4pt1jIdQXT231b+uyFtgJkRgix8= =Z79r -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Markus Koschany (on-list) Markus Koschany (off-list) Prev by Date: [SECURITY] [DSA 6328-1] tomcat10 security update Next by Date: [SECURITY] [DSA 6331-1] keystone security update Previous by thread: [SECURITY] [DSA 6328-1] tomcat10 security update Next by thread: [SECURITY] [DSA 6331-1] keystone security update Index(es): Date Thread

Share this article